CVE-2019-25224
critical · 9.8The WP Database Backup plugin for WordPress is vulnerable to OS Command Injection in versions before 5.2 via the mysqldump function. This vulnerability allows unauthenticated attackers to execute arbitrary commands on the host operating system.
9.8
CVSS
21.4%
EPSS (exploit prob.)
97th
EPSS percentile
2025-07-25
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-78
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| wpseeds | wp_database_backup | < 5.2 |
Check a specific version with /api/v1/cve/match.
References
- https://blog.sucuri.net/2019/06/os-command-injection-in-wp-database-backup.html
- https://packetstormsecurity.com/files/153781/
- https://plugins.trac.wordpress.org/changeset/2078035/wp-database-backup
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/multi/http/wp_db_backup_rce.rb
- https://www.wordfence.com/blog/2019/05/os-command-injection-vulnerability-patched-in-wp-database-backup-plugin/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/d21cf285-9d75-43a2-9e81-67116f0bf896?source=cve
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2019-25224